As if ransomware weren't already causing enough problems on computers, we now discover that its developers are redirecting resources towards mobile devices. According to McAfee's mobile malware research division, "ElGato" is a ransomware designed to infect the Android operating system, with the ability to encrypt users' personal files, steal SMS messages, and of course, block access to the device.
Why Mobile Devices Are a Prime Target
It's no secret that mobile devices have become a very tempting target for malware developers. The average user often stores credentials for various services on their smartphone, and more than a few already make electronic payments via mobile. Imagine what an attacker could do with access to Facebook, Snapchat, Instagram, Dropbox, PayPal, Gmail, and other similar platforms. The user's "digital life" would descend into chaos, although there is a much more interesting and lucrative option: holding all those services hostage. Ransomware on computers has a certain preference for government agency terminals, hospitals, and schools, but if it moves onto mobile devices, the "rewards" could be even greater.
Meet ElGato
This brings us to a recent discovery by McAfee's mobile malware research division. The division found a ransomware sample with botnet capabilities that they named "ElGato" because they found the image of a cat in a window within its code. The most curious thing is that "ElGato" would serve as a kind of demo for the commercialization of kits that a criminal could deploy on the Web with basic knowledge. Another detail confirming its role as a demo is that all communication with the command and control center goes through HTTP, without any encryption. This allowed researchers to get a clearer idea of its attack types: encrypting data on the SD card, automatically sending and deleting SMS messages, and locking the screen.
A Growing Threat
Although we are convinced that the "ElGato" adventure has come to an end (its main service runs on legitimate servers, and McAfee has already contacted the provider to get it removed from the Web), nothing prevents it from evolving into something much more dangerous. In other words, ElGato is a ransomware in development. As always, those Android users who use alternative stores or manually download APKs must ensure that the source of the files is reliable and "clean".